Назад
21 час назад

Third Party Risk Analyst, Security GRC (AI)

255 000 - 270 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Third Party Risk Analyst, Security GRC (Cybersecurity): Managing risk for mission-critical vendor and partner relationships with an accent on compute, data center, and data-pipeline infrastructure. Focus on driving remediation for highest-risk vendors and tuning LLM-backed AI risk agents for intake and evidence collection.

Location: Hybrid (San Francisco, CA); Must be in one of the offices at least 25% of the time

Salary: $255,000 - $270,000 USD

Company

AI safety and research company focused on creating reliable, interpretable, and steerable AI systems.

What you will do

  • Own the Mission Critical vendor portfolio, focusing on failover planning and single-point-of-failure analysis.
  • Manage Highest-Risk vendor portfolios by aligning assessment depth with exposure and driving remediation.
  • Coordinate vendor incident response, including impact assessments and post-incident risk treatment.
  • Conduct inherent risk assessments through an AI-driven intake workflow.
  • Tune and maintain the TPRM Risk Agent using prompt development, backtest calibration, and output QA.
  • Report on KPI/KRI regarding portfolio coverage and cycle time.

Requirements

  • Experience running end-to-end third party or vendor risk assessments at a technology company.
  • Strong understanding of risk fundamentals (inherent, residual, control effectiveness).
  • Ability to assess security, privacy, compliance, and operational risk domains.
  • Experience building or tuning LLM-backed workflows or agents in a risk, compliance, or operations context.
  • Proficiency with procurement or GRC platforms.
  • Knowledge of business continuity, disaster recovery, and concentration risk.

Nice to have

  • Experience assessing cloud infrastructure, data center, or data-pipeline vendors.
  • Experience with vendor financial health or solvency screening.
  • Familiarity with SOX, SOC 2, or ISO 27001 third party management controls.
  • Exposure to exit planning, contract termination provisions, or supplier failover testing.

Culture & Benefits

  • Collaborative "big science" research environment.
  • Competitive compensation and optional equity donation matching.
  • Generous vacation and parental leave.
  • Flexible working hours and high-quality office space.
  • Visa sponsorship availability.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →